> Source: [sk119143](https://support.checkpoint.com/results/sk/sk119143)

# sk119143 - "encryption fail reason: Cannot change dynamic vpn interface - new interface not accepted by rule" log 

| Property | Value |
|----------|-------|
| Solution ID | sk119143 |
| Date Created | 2017-07-19 |
| Last Modified | 2025-01-22 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20, R81.10 (EOS), R81 (EOS) |

## Symptoms

- "`encryption fail reason: Cannot change dynamic vpn interface - new interface not accepted by rule`" log in SmartLog.

## Cause

When dynamic routing VPN is enabled on the Security Gateway, and complex encryption domain is configured (either by encryption for Remote Access VPN, or by the "`for comm`" token in the *$FWDIR/conf/vpn_route.conf* file for Site-to-Site VPN), a connection towards the complex encryption domain can be tagged as dynamic only if there is a route via a VTI interface.

If the relevant route via VTI interface does not exist, or if the route to the VTI interface is lost during the dynamic VPN connection, the connection we be tagged as "MY_COMPLEX_ENCDOM" and will be released in clear.

If any of these conditions met, then Security Gateway checks whether the connection is allowed to pass on the new dynamic interface:

* this is a Dynamic VPN connection from a Client side
* this is a Dynamic VPN connection from a Server side
* this is a Dynamic VPN connection that belongs to complex encryption domain

Security Gateway checked the connection and made one of the following decisions:

* Do not change the interface and drop the packet
* Do not change the interface
* Do not change the interface due to an implied rule

Note: To see the detailed information, a VPN Kernel Debug is required ('`fw ctl debug -m VPN + policy`').

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
